Contact Us
IT Total Care

Month: September 2026

Caregiver wearing a photo identification badge resting a hand on a seated older woman holding a cane, the client records behind California's 30-day breach notification

How to Meet California’s 30-Day Breach Notification Deadline

At 4:40 on a Friday afternoon, an office coordinator at a home care agency in the East Bay opens the shared drive to pull the weekend’s care plans and finds every file renamed. She calls the owner, who calls the person…

Read More
Nurse in blue scrubs holding hands with an older man in a wheelchair beside tall windows, the client relationships that cybersecurity for home care agencies exists to protect.

Cybersecurity for Home Care Agencies: What the Law Requires Even Without HIPAA

Cybersecurity for home care agencies is governed by California law and private contracts far more often than it is governed by HIPAA. Most private-pay agencies are not HIPAA covered entities, and a great deal of published guidance stops at that sentence….

Read More
A home care caregiver checking a scheduling app on a smartphone outside a client’s home

Caregiver Technology Adoption in Home Care: What Actually Works in the Field

Home care agencies have no shortage of technology pitched to them. Scheduling platforms, AI-driven caregiver matching, remote monitoring, telehealth integrations, wearable sensors – the vendor list grows every year, and so does the marketing promising that the right app will solve…

Read More
Smiling specialist wearing a headset at an office workstation, fielding questions like whether you can outsource the HIPAA security officer role to an IT provider.

Can You Outsource the HIPAA Security Officer Role to Your IT Provider?

Can you outsource the HIPAA security officer role along with the rest of your technology? It is the question that produces the longest pause when a surveyor asks a home health administrator to name the agency’s Security Official. Agencies that handed…

Read More
Support team in headsets working through a screen together at a shared desk, the vendor coordination a HIPAA shared responsibility matrix puts in writing.

How to Build a HIPAA Shared Responsibility Matrix With Your IT Provider

A HIPAA shared responsibility matrix answers a question most home health agencies cannot answer on the spot: who owns each compliance function, the agency or the IT provider. Ask an administrator who approves the risk analysis and you will usually get…

Read More
Older adult and a younger man reviewing a laptop together at her kitchen table, the setting behind decisions about outsourcing HIPAA compliance for home health agencies.

Outsourcing HIPAA Compliance for Home Health Agencies: What You Can’t Hand Over

Outsourcing HIPAA compliance for home health agencies moves the work of compliance, not the accountability for it. An IT provider can implement the safeguards, run the monitoring, and produce the evidence. Your agency still answers for the decisions underneath all of…

Read More
Nurse in navy scrubs beside an older client seated on a couch at home, the setting behind the question: is a stolen encrypted laptop a reportable HIPAA breach.

Is a Stolen Encrypted Laptop a Reportable HIPAA Breach?

Is a stolen encrypted laptop a reportable HIPAA breach? Usually not under federal law, and that answer holds only if the agency can prove three specific things about the device after it is already gone. For a California home health agency…

Read More
Home health aide in blue scrubs brushing a seated client's hair during a home visit, the care setting behind how to report a medical information breach to CDPH.

How to Report a Medical Information Breach to CDPH in 15 Business Days

This guide explains why reporting a medical information breach to CDPH matters for a California licensed agency, how to work through the filing step by step on your own, and how IT Total Care builds the detection and evidence the filing…

Read More
Caregiver holding an older adult's hand beside a walking cane during a home visit, the patient relationship behind HIPAA breach notification for home health agencies.

HIPAA Breach Notification for Home Health Agencies: 60 Days Is the Outer Limit

HIPAA breach notification for home health agencies has one federal deadline: 60 calendar days from the day a breach is discovered. That is the outer limit, not a target. An agency that sends notice on day 55 can still be found…

Read More
Clinician with a stethoscope reading patient records on a tablet, the access that decides whether home health agencies need a BAA with a staffing agency.

Do Home Health Agencies Need a BAA With a Staffing Agency?

Do home health agencies need a BAA with a staffing agency? Not always, and not never. The answer turns on who controls the clinician’s work, which means two agencies using the same staffing firm can land in different places and both…

Read More